Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Dwolla is a US bank transfer and ACH payments API that runs mostly server to server, with an optional JavaScript drop in component and bank verification flows often paired with Plaid.
Dwolla is a bank transfer and ACH payments platform operated by Dwolla Inc. in Des Moines, Iowa, in the United States. It is mainly an API that moves funds between bank accounts on behalf of software platforms, with an optional drop in component for embedding flows.
Because Dwolla works server to server, the browser footprint is small. The optional drop in component and the dashboard set functional cookies needed to operate, while the substantive processing of bank account and identity data happens through the API. Bank verification is often handled with a partner such as Plaid.
The functional cookies used to deliver a transfer the user requested are generally exempt from the consent rule in the ePrivacy Directive. The processing of bank and identity data rests on contract, on legal obligations for financial rules, and on legitimate interests for fraud prevention.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Consent is generally not required for the payment transaction itself because it is strictly necessary to provide the service the user asked for. If a platform adds analytics or marketing around the Dwolla flow, those non essential cookies need prior consent.
Dwolla processes data in the United States, so European platforms carry out a transfer to a third country. This should be covered by Standard Contractual Clauses, a transfer impact assessment, and supplementary safeguards, with attention to any bank verification partner involved.
Sign a data processing agreement with Dwolla, document the US transfer and any verification partner, and disclose the functional cookies of the drop in and dashboard. Obtain end user consent for using their data as required by the Dwolla platform agreement and keep a clear privacy notice.
Websites using Dwolla must obtain user consent under GDPR regulations.
DPIA considerations
Risk on the embed side is limited because Dwolla is mainly a backend API that sets only functional cookies. A DPIA should focus on the bank account and identity data flowing to the US, the role of bank verification partners such as Plaid, and the financial nature of the data.
Sample consent text
We use Dwolla to move funds between bank accounts when you request a transfer. Dwolla operates mainly as a backend service and uses only functional cookies needed to deliver it. Your bank account details are processed to complete the payment you have asked us to make.
Third-party domains contacted
dwolla.comapi.dwolla.comcdn.dwolla.comdashboard.dwolla.comaccounts.dwolla.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| Drop in session cookie | Third-party | Session | Maintains the state of the Dwolla drop in component while the user completes a flow |
| Dashboard session cookie | First-party | Session | Keeps the user authenticated in the Dwolla dashboard for the duration of the session |
| Functional preference cookie | First-party | 1 year | Stores basic functional and security preferences for the Dwolla interface |
Dwolla uses cookies for user preferences — inform visitors with a consent banner.
Dwolla is mainly a backend API, so its browser footprint is small. The optional drop in component and the dashboard set functional cookies needed to operate the interface, rather than analytics or marketing cookies on the merchant page.
Consent is generally not required for the payment transaction itself because the functional cookies are strictly necessary to deliver the transfer the user requested. Consent applies only if a platform adds non essential analytics or marketing around the flow.
Processing rests on performance of a contract under Article 6(1)(b) for executing bank transfers, legal obligation under Article 6(1)(c) for financial and anti money laundering rules, and legitimate interests under Article 6(1)(f) for fraud prevention.
Yes. Dwolla Inc. processes data in the United States, so European platforms carry out a transfer to a third country. This should be covered by Standard Contractual Clauses and supplementary safeguards, including any bank verification partner such as Plaid.
A DPIA is advisable because Dwolla processes bank account and identity data and transfers it to the US, even though the browser footprint is small. The assessment should cover the financial data, the US transfer and any verification partner involved.
Sign a data processing agreement with Dwolla, document the US transfer and any verification partner, and disclose the functional cookies of the drop in and dashboard. Obtain end user consent for using their data as required by the Dwolla platform agreement.
Alternatives for bank transfer and ACH payments include Stripe ACH, Plaid with a processor, GoCardless for direct debit, and Modern Treasury. Each differs in server locations, cookie behaviour and transfer mechanisms that should be reviewed individually.
Add a short Dwolla entry that explains it is mainly a backend API and lists the functional cookies of the drop in and dashboard with their purposes and durations. Note the US data transfer and update the entry if you embed more of the Dwolla flow.